cbcvebase.
CVE-2023-53220
published 2025-09-15

CVE-2023-53220: In the Linux kernel, the following vulnerability has been resolved: media: az6007: Fix null-ptr-deref in az6007_i2c_xfer() In az6007_i2c_xfer, msg is…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.3th percentile
In the Linux kernel, the following vulnerability has been resolved: media: az6007: Fix null-ptr-deref in az6007_i2c_xfer() In az6007_i2c_xfer, msg is controlled by user. When msg[i].buf is null and msg[i].len is zero, former checks on msg[i].buf would be passed. Malicious data finally reach az6007_i2c_xfer. If accessing msg[i].buf[0] without sanity check, null ptr deref would happen. We add check on msg[i].len to prevent crash. Similar commit: commit 0ed554fd769a ("media: dvb-usb: az6027: fix null-ptr-deref in az6027_i2c_xfer()")

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.55-1 (bookworm)linux 6.1.55-1 (bookworm)
linuxlinux
linuxlinux>= caa1a700ed2a06a831e6a7db5d9f213fc63caee3 < c6763fefa267f6e62595a6ac1f57815d99fc90b7c6763fefa267f6e62595a6ac1f57815d99fc90b7
linuxlinux>= caa1a700ed2a06a831e6a7db5d9f213fc63caee3 < adcb73f8ce9aec48b1f85223f401c1574015d8d2adcb73f8ce9aec48b1f85223f401c1574015d8d2
linuxlinux>= caa1a700ed2a06a831e6a7db5d9f213fc63caee3 < 991c77fe18c6f374bbf83376f8c42550aa565662991c77fe18c6f374bbf83376f8c42550aa565662
linuxlinux>= caa1a700ed2a06a831e6a7db5d9f213fc63caee3 < a9def3e9718a4dc756f48db147d42ec41a966240a9def3e9718a4dc756f48db147d42ec41a966240
linuxlinux>= caa1a700ed2a06a831e6a7db5d9f213fc63caee3 < 5b1ea100ad3695025969dc4693f307877fb688d65b1ea100ad3695025969dc4693f307877fb688d6
linuxlinux>= caa1a700ed2a06a831e6a7db5d9f213fc63caee3 < 6ab7ea4e17d6a605d05308adf8f3408924770cba6ab7ea4e17d6a605d05308adf8f3408924770cba
linuxlinux>= caa1a700ed2a06a831e6a7db5d9f213fc63caee3 < a1110f19d4940e4185251d072cbb0ff51486a1e7a1110f19d4940e4185251d072cbb0ff51486a1e7
linuxlinux>= caa1a700ed2a06a831e6a7db5d9f213fc63caee3 < 1047f9343011f2cedc73c64829686206a7e9fc3f1047f9343011f2cedc73c64829686206a7e9fc3f
linuxlinux_kernel< 4.14.3264.14.326
linuxlinux_kernel>= 0 < 5.10.197-15.10.197-1
linuxlinux_kernel>= 0 < 6.1.55-16.1.55-1
linuxlinux_kernel>= 0 < 6.5.6-16.5.6-1
linuxlinux_kernel>= 0 < 6.5.6-16.5.6-1
linuxlinux_kernel>= 4.15 < 4.19.2954.19.295
linuxlinux_kernel>= 4.20 < 5.4.2575.4.257
linuxlinux_kernel>= 5.11 < 5.15.1335.15.133
linuxlinux_kernel>= 5.16 < 6.1.556.1.55
linuxlinux_kernel>= 5.5 < 5.10.1975.10.197
linuxlinux_kernel>= 6.2 < 6.5.56.5.5

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.